Skip to content
Transcriwise

Security & Compliance

Model training is disabled by default.

Encryption at rest and in transit, LGPD-oriented processes, and granular workspace access controls.

AES-256TLSRBAC2FA
Real workspace security settings
Real workspace screen. Features vary by plan and configuration.

Infrastructure

What is enabled and what is an Enterprise option.

The matrix keeps default controls, contractual options, and roadmap items separate.

ControlScopeDefaultEnterprise

AES-256 Encryption

AES-256 for stored objects, with dedicated KMS or BYOK according to workspace policy.

StorageEnabledKMS / BYOK

TLS in transit

Communication between the browser and service endpoints uses TLS in transit.

TrafficEnabledAdditional policies

Access control

RBAC with permissions per workspace, per user, and per resource. Every action is logged.

WorkspaceRBACSSO / SAML

2FA Authentication

2FA available for all plans. SSO/SAML for Enterprise.

Account2FASSO / SAML

Audit logs

Complete verification of all operations. Who accessed, when, and what.

OperationsProduct recordsExtended governance

Backup and DR

Automatic backups with configurable retention. Incident recovery without data loss.

ContinuityRecovery proceduresContractual policy

Data handling

How we handle your data

From upload to deletion, each category has a purpose and an applicable policy.

01

Uploaded audio

Processed by the selected ASR engine and retained according to workspace settings until user deletion or the applicable policy.

02

Transcriptions

Stored encrypted in your workspace. Accessible only by you and authorized members. Exportable at any time.

03

Personal data

We only collect what is necessary to operate the service (email, name, plan). Never sold. Never shared for marketing.

04

AI models

Training opt-in is disabled by default. Processing by selected AI providers follows their enterprise terms and applicable retention policies.

05

Integrations

Minimal and revocable access. We connect with Google Drive, Dropbox, Zoom, and Slack — but only access what you authorize, when you authorize it.

Compliance

LGPD by design

The product was built with LGPD processes in mind.

  • Right of accessArt. 18, I
  • Right of correctionArt. 18, III
  • Right of deletionArt. 18, VI
  • Right of portabilityArt. 18, V
  • Right to revoke consentArt. 18, IX
  • Right to information on sharingArt. 18, VII

Certifications

Certifications and roadmap

Implemented controls are not presented as independent certifications.

LGPD processes

Operational practice and documentation

Active

AES-256 at rest

Implemented control

Active

TLS in transit

Implemented control

Active

SOC 2 Type II

In preparation

Planned

ISO 27001

Roadmap

Planned

Frequently asked questions

Security questions

Have questions about security?

For DPA requests, subprocessor lists, or security reviews, write directly to the responsible team.

security@transcriwise.com
Transcriwise